GPEN Advanced Password Attacks Practice Question
During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?
⚠ Common exam trap
The trap here is assuming that Mimikatz can parse offline NTDS.dit files, when it is primarily used for live credential extraction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
secretsdump.py
secretsdump.py is the correct tool because it can parse an offline NTDS.dit file when paired with the SYSTEM hive to decrypt the encrypted password hashes. It extracts NTLM hashes and other secrets, which can then be cracked offline. Mimikatz is used for live memory extraction, while hashcat and John the Ripper are cracking tools that require pre-extracted hashes. Therefore, secretsdump.py is the only tool that directly accomplishes the extraction from the given files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mimikatz
Why it's wrong here
Mimikatz is primarily used for live credential extraction from memory, such as LSASS process, and can perform DCSync attacks against a running domain controller. However, it is not designed to parse offline NTDS.dit files directly. While Mimikatz has some capabilities to read registry hives, it lacks the comprehensive offline NTDS.dit parsing functionality that secretsdump.py provides, making it less suitable for this specific task.
- ✗
John the Ripper
Why it's wrong here
John the Ripper is a password cracking tool similar to hashcat. It can crack various hash formats but does not include functionality to parse NTDS.dit or SYSTEM hive files for hash extraction. While it has some scripts for extracting hashes from other sources, it is not designed for offline NTDS.dit parsing. Thus, it is not the correct tool for this scenario.
- ✗
hashcat
Why it's wrong here
Hashcat is a password cracking tool that takes already extracted hashes and attempts to recover plaintext passwords. It cannot parse NTDS.dit or SYSTEM hive files to extract hashes; it requires the hashes to be provided in a specific format. Therefore, hashcat is not the appropriate tool for extracting hashes from these files, though it would be used in a subsequent cracking phase.
- ✓
secretsdump.py
Why this is correct
secretsdump.py from Impacket can parse an offline NTDS.dit file when provided with the SYSTEM hive to decrypt the encrypted hash data. It extracts NTLM hashes, Kerberos keys, and other secrets. This tool is specifically designed for this purpose and is widely used in penetration testing to obtain domain credentials from extracted Active Directory databases. It supports both online and offline extraction, making it suitable for this scenario.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.